CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Description
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-109 · CAPEC-110 · CAPEC-470 · CAPEC-66 · CAPEC-7
CVEs mapped to this weakness (20,855)
page 196 of 1,043| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-76602 | Cri | 0.60 | — | 0.00 | Aug 22, 2026 | Joomla Extension - fabrikar.com - Unauthenticated SQL injection in ORDER BY in Fabrik < 4.7.2 - The order parameter in list models is used in queries without validation, allowing read SQLi vectors. | ||
| CVE-2026-76571 | Cri | 0.60 | — | 0.00 | Aug 22, 2026 | Joomla Extension - fabrikar.com - Unauthenticated SQL injection in list filter condition parameter in Fabrik < 4.7.2 - The condition parameter passed to a list filter is concatenated verbatim into the WHERE clause built by getFilterQuery(). An unauthenticated attacker can supply… | ||
| CVE-2026-68566 | Cri | 0.60 | 9.3 | 0.00 | Aug 20, 2026 | Unauthenticated SQL Injection in BookingPress Appointment Booking Pro <= 6.0.2 versions. | ||
| CVE-2026-66680 | Cri | 0.60 | 9.3 | 0.00 | Aug 20, 2026 | Unauthenticated SQL Injection in Locatoraid Store Locator <= 3.9.72 versions. | ||
| CVE-2026-66649 | Cri | 0.60 | 9.3 | 0.00 | Aug 20, 2026 | Unauthenticated SQL Injection in Directory Pro <= 2.5.8 versions. | ||
| CVE-2026-66609 | Cri | 0.60 | 9.3 | 0.00 | Aug 20, 2026 | Unauthenticated SQL Injection in TheGem (Elementor) <= 5.12.3 versions. | ||
| CVE-2026-66593 | Cri | 0.60 | 9.3 | 0.00 | Aug 20, 2026 | Unauthenticated SQL Injection in Security & Malware scan by CleanTalk <= 2.184 versions. | ||
| CVE-2026-66592 | Cri | 0.60 | 9.3 | 0.00 | Aug 20, 2026 | Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11 versions. | ||
| CVE-2025-15688 | Cri | 0.60 | 9.3 | 0.00 | Aug 20, 2026 | Unauthenticated SQL Injection in Capella <= 2.5.5 versions. | ||
| CVE-2026-75954 | Cri | 0.60 | — | 0.00 | Aug 19, 2026 | Joomla Extension - cmsjunkie.com - SQL injection in trips search in J-BusinessDirectory < 6.2.3 - Search keywords and ORDER BY were concatenated into SQL. 6.2.3 quotes keywords and allow-lists the sort clause. | ||
| CVE-2026-74804 | Cri | 0.60 | — | 0.00 | Aug 19, 2026 | Joomla Extension - yootheme.com - Unauthenticated SQL injection in ItemController::element() in Zoo < 4.1.64 - The filter_type request value is interpolated into the query as a.type = "..." and the type_filter array as a.type IN ("..."), with no quoting or escaping. | ||
| CVE-2026-73391 | Cri | 0.60 | 9.3 | 0.00 | Aug 19, 2026 | Unauthenticated SQL Injection in Total Donations <= 2.0.5 versions. | ||
| CVE-2026-73388 | Cri | 0.60 | 9.3 | 0.00 | Aug 19, 2026 | Unauthenticated SQL Injection in Nikstore Core <= 1.5 versions. | ||
| CVE-2026-73185 | Cri | 0.60 | 9.3 | 0.00 | Aug 19, 2026 | Unauthenticated SQL Injection in NGG Smart Image Search < 4.0.0 versions. | ||
| CVE-2026-73183 | Cri | 0.60 | 9.3 | 0.00 | Aug 19, 2026 | Unauthenticated SQL Injection in Maps Marker Pro <= 4.32 versions. | ||
| CVE-2026-74015 | Cri | 0.60 | 9.3 | 0.00 | Aug 18, 2026 | Unauthenticated SQL Injection in Readabler < 2.0.18 versions. | ||
| CVE-2026-73365 | Cri | 0.60 | 9.3 | 0.00 | Aug 18, 2026 | Unauthenticated SQL Injection in JetAppointment <= 2.5.2 versions. | ||
| CVE-2026-73355 | Cri | 0.60 | 9.3 | 0.00 | Aug 18, 2026 | Unauthenticated SQL Injection in Affiliates Manager <= 2.9.53 versions. | ||
| CVE-2026-73339 | Cri | 0.60 | 9.3 | 0.00 | Aug 18, 2026 | Unauthenticated SQL Injection in Modern Events Calendar < 7.35.0 versions. | ||
| CVE-2026-73187 | Cri | 0.60 | 9.3 | 0.00 | Aug 18, 2026 | Unauthenticated SQL Injection in Sticky Chat Widget <= 1.4.2 versions. |
- risk 0.60cvss —epss 0.00
Joomla Extension - fabrikar.com - Unauthenticated SQL injection in ORDER BY in Fabrik < 4.7.2 - The order parameter in list models is used in queries without validation, allowing read SQLi vectors.
- risk 0.60cvss —epss 0.00
Joomla Extension - fabrikar.com - Unauthenticated SQL injection in list filter condition parameter in Fabrik < 4.7.2 - The condition parameter passed to a list filter is concatenated verbatim into the WHERE clause built by getFilterQuery(). An unauthenticated attacker can supply…
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in BookingPress Appointment Booking Pro <= 6.0.2 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in Locatoraid Store Locator <= 3.9.72 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in Directory Pro <= 2.5.8 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in TheGem (Elementor) <= 5.12.3 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in Security & Malware scan by CleanTalk <= 2.184 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in Capella <= 2.5.5 versions.
- risk 0.60cvss —epss 0.00
Joomla Extension - cmsjunkie.com - SQL injection in trips search in J-BusinessDirectory < 6.2.3 - Search keywords and ORDER BY were concatenated into SQL. 6.2.3 quotes keywords and allow-lists the sort clause.
- risk 0.60cvss —epss 0.00
Joomla Extension - yootheme.com - Unauthenticated SQL injection in ItemController::element() in Zoo < 4.1.64 - The filter_type request value is interpolated into the query as a.type = "..." and the type_filter array as a.type IN ("..."), with no quoting or escaping.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in Total Donations <= 2.0.5 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in Nikstore Core <= 1.5 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in NGG Smart Image Search < 4.0.0 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in Maps Marker Pro <= 4.32 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in Readabler < 2.0.18 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in JetAppointment <= 2.5.2 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in Affiliates Manager <= 2.9.53 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in Modern Events Calendar < 7.35.0 versions.
- risk 0.60cvss 9.3epss 0.00
Unauthenticated SQL Injection in Sticky Chat Widget <= 1.4.2 versions.